Subject Matter Expert (SME) Cybersecurity Consultant – Control Testing

Kaizen Lab Inc.

Charlotte (NC)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Kaizen Lab Inc. is seeking an SME Cybersecurity Consultant to lead and guide control testing efforts for federal and critical industry clients.

The role requires 10+ years in cybersecurity with deep expertise in NIST 800-53 v5, NIST 800-37, and FISMA, and the ability to deliver SSPs, SARs, and POA&Ms. You will collaborate with IT, security, and audit teams, providing mentorship to assessment staff and supporting RMF-based authorization processes.

Qualifications

  • In-depth knowledge of federal control testing and RMF-based assessments.
  • ],
  • job_responsibilities_description:[“Lead and perform comprehensive cybersecurity control assessments in accordance with NIST 800-53 v5, NIST 800-37, and FISMA requirements.”,
  • Serve as the SME for control testing methodologies and mentor assessment teams.
  • Review and validate control implementation and effectiveness, ensuring compliance with federal regulations and organizational policies.
  • Develop and deliver SSPs, SARs, and POA&Ms.
  • Analyze security documentation and evidence for compliance with security and privacy controls.
  • Collaborate with IT, security, and audit teams to identify and mitigate risks.
  • Provide RMF process expertise to support system authorization and accreditation.
  • Assist in audits and regulatory inspections; stay current with regulatory changes.
  • Communicate findings to technical and non-technical stakeholders including senior leadership.

Responsibilities

  • Lead and perform comprehensive cybersecurity control assessments in accordance with NIST 800-53 v5, NIST 800-37, and FISMA requirements.
  • Serve as the subject matter expert (SME) for control testing methodologies, providing guidance and mentorship to assessment teams.
  • Review and validate control implementation and effectiveness, ensuring compliance with federal regulations and organizational policies.
  • Develop and deliver key artifacts, including SSPs, SARs, and POA&Ms.
  • Analyze security documentation, configurations, and evidence to assess compliance with security and privacy controls.
  • Collaborate with cross-functional teams, including IT, security, and audit teams, to identify, document, and mitigate risks.
  • Provide technical expertise in the implementation of the RMF process, supporting system authorization and accreditation.
  • Assist in the preparation for audits, inspections, and other regulatory assessments, ensuring successful outcomes.
  • Stay informed about evolving federal cybersecurity regulations, standards, and threats to provide proactive recommendations.
  • Communicate assessment findings and recommendations effectively to both technical and non-technical stakeholders, including senior leadership and government clients.

Skills

Control testing & compliance
RMF knowledge
NIST 800-53 v5
NIST 800-37
FISMA
Government briefing
Strong communication
SSP/SAR/POA&M prep

Education

Bachelor's degree in Cybersecurity/IT

Job description

Position Summary

The SME Cybersecurity Consultant will play a critical role in conducting, guiding, and validating control testing efforts for federal and critical industry clients. This individual will leverage 10+ years of experience in cybersecurity, with a focus on compliance, control assessments, and risk management. The ideal candidate will be a recognized expert in NIST 800-53, NIST 800-37, and FISMA, with strong analytical and communication skills to support high-profile engagements.


Key Responsibilities


  • Lead and perform comprehensive cybersecurity control assessments in accordance with NIST 800-53 v5, NIST 800-37, and FISMA requirements.

  • Serve as the subject matter expert (SME) for control testing methodologies, providing guidance and mentorship to assessment teams.

  • Review and validate control implementation and effectiveness, ensuring compliance with federal regulations and organizational policies.

  • Develop and deliver key artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plan of Action and Milestones (POA&Ms).

  • Analyze security documentation, configurations, and evidence to assess compliance with security and privacy controls.

  • Collaborate with cross-functional teams, including IT, security, and audit teams, to identify, document, and mitigate risks.

  • Provide technical expertise in the implementation of the Risk Management Framework (RMF) process, supporting system authorization and accreditation.

  • Assist in the preparation for audits, inspections, and other regulatory assessments, ensuring successful outcomes.

  • Stay informed about evolving federal cybersecurity regulations, standards, and threats to provide proactive recommendations.

  • Communicate assessment findings and recommendations effectively to both technical and non-technical stakeholders, including senior leadership and government clients.


Qualifications

Required Experience and Skills:



  • MUST BE A U.S. CITIZEN

  • 10+ years of experience in cybersecurity, with a strong focus on control testing and compliance in federal environments.

  • In-depth knowledge of NIST 800-53 v5, NIST 800-37, and FISMA frameworks and requirements.

  • Proven expertise in conducting control assessments, documenting findings, and developing remediation plans.

  • Strong understanding of the Risk Management Framework (RMF) process and its application to federal systems.

  • Experience in developing security artifacts, including SSPs, SARs, and POA&Ms.

  • Exceptional analytical skills, with the ability to assess complex systems and identify compliance gaps.

  • Excellent verbal and written communication skills, with experience briefing senior executives and federal clients.

  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field.


Preferred Qualifications:



  • Certifications such as CISSP, CAP, CISM, or CRISC.

  • Experience in privacy control assessments and integrating privacy requirements into security programs.

  • Familiarity with cybersecurity tools and technologies used for testing and validation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Specialist
Cybersecurity Specialist

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Cybersecurity Program Manager – Controls Testing
Cybersecurity Program Manager – Controls Testing

Kaizen Lab Inc. • Richmond (VA)

On-site
USD 140,000 - 190,000
Cybersecurity Subject Matter Expert (SME)
Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Security Subject Matter Expert (Security)
Cyber Security Subject Matter Expert (Security)

Snowrelic Inc • United States

On-site
USD 100,000 - 130,000
Senior Cybersecurity Subject Matter Expert (SME)
Senior Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Hybrid work with on-site classified
SIPRNet access may be required
Senior Federal Cybersecurity Controls SME (NIST RMF)
Senior Federal Cybersecurity Controls SME (NIST RMF)

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Cybersecurity Subject Matter Expert (SME)
Cybersecurity Subject Matter Expert (SME)

Unity Technologies Corporation • Fort Belvoir (VA)

On-site
USD 120,000 - 150,000
Senior Cybersecurity Financial Compliance SME
Senior Cybersecurity Financial Compliance SME

ASRC Federal • California (MO), Northern (KY)

Hybrid
USD 140,000 - 190,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Cybersecurity Subject Matter Expert Lead
Cybersecurity Subject Matter Expert Lead

Goldbelt, Inc. • New Cumberland

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+3